Security researchers have highlighted ongoing exploitation and new vulnerabilities in the NTLM authentication protocol, which remains widely used in enterprise environments despite its well-known weaknesses. Recent research details multiple attack vectors, including hash leakage, coercion-based attacks, credential forwarding, and man-in-the-middle (MitM) techniques, as well as the continued use of NTLM in modern operating systems and legacy applications. Notable campaigns in 2025 have leveraged vulnerabilities such as CVE-2024-43451, CVE-2025-24054, and CVE-2025-33073 to deliver malware and conduct targeted attacks, particularly in Russia and Uzbekistan.
Proof-of-concept exploits for NTLM elevation of privilege vulnerabilities have been released, further increasing the risk to organizations that have not yet migrated away from NTLM or implemented robust mitigations. Security experts recommend disabling or limiting NTLM, enabling message signing, and monitoring authentication logs to reduce exposure. The persistence of NTLM in critical infrastructure underscores the urgent need for organizations to transition to more secure authentication protocols and to remain vigilant against evolving exploitation techniques targeting NTLM weaknesses.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
A later report again emphasized that legacy NTLM weaknesses such as CVE-2024-43451 continued to pose risk in 2025. The coverage reinforced the persistence of the issue rather than introducing a separate incident.
Kaspersky published analysis describing multiple NTLM vulnerabilities, including CVE-2024-43451, CVE-2025-24054, CVE-2025-24071, and CVE-2025-33073, as actively exploited in 2025. The report highlighted continued attacker reliance on NTLM even as Microsoft moves to phase out the protocol.
A proof-of-concept exploit was publicly released for a Windows NTLM elevation-of-privilege vulnerability, increasing the risk of wider abuse. The reporting aligns this with the broader 2025 wave of NTLM-related exploitation and research attention.
Microsoft released a patch for CVE-2025-33073, an NTLM elevation-of-privilege vulnerability. Subsequent reporting indicated exploit code was later released and the flaw became part of broader concern over ongoing NTLM exploitation.
The Head Mare threat actor leveraged NTLM vulnerabilities in campaigns targeting organizations in Russia and Uzbekistan, using techniques such as phishing with malicious .url or .library-ms files and delivering malware including PhantomCore. The activity showed NTLM abuse expanding across multiple regions in 2025.
Microsoft released patches for CVE-2025-24054 and CVE-2025-24071, two additional NTLM-related vulnerabilities that enabled credential theft or related abuse paths. Reporting later noted both flaws were exploited in the wild in 2025.
Threat actor BlindEagle used CVE-2024-43451 in targeted attacks against organizations in Latin America, delivering malware such as Remcos RAT and AveMaria/Warzone via malicious files. The campaigns demonstrated continued real-world abuse of NTLM weaknesses after disclosure.
Microsoft released a fix for CVE-2024-43451, an NTLM-related vulnerability that could leak credentials with minimal user interaction. Later reporting says the flaw was subsequently exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.